Latest Cybersecurity News and Articles


Critical Flaw in Cisco IP Phone Series Exposes Users to Command Injection Attack

02 March 2023
The vulnerability, tracked as CVE-2023-20078, is rated 9.8 out of 10 on the CVSS scoring system and is described as a command injection bug in the web-based management interface arising due to insufficient validation of user-supplied input.

SysUpdate Malware Strikes Again with Linux Version and New Evasion Tactics

02 March 2023
The threat actor known as Lucky Mouse has developed a Linux version of a malware toolkit called SysUpdate, expanding on its ability to target devices running the operating system. The oldest version of the updated artifact dates back to July 2022, with the malware incorporating new features designed to evade security software and resist reverse engineering. Cybersecurity company Trend Micro said

WhiteSnake Promotes Windows and Linux Variants with a MaaS Model

02 March 2023
A new malware stealer called WhiteSnake has surfaced to steal credit card numbers and other sensitive information from Windows and Linux users. The Windows variant, comparatively an older and mature variant, is capable of stealing sensitive data from different browsers. The info-stealer can steal files from various cryptocurrency wallets such as Atomic, Bitcoin, Coinomi, Electrum, Exodus, and Guarda.

Critical Flaw in Cisco IP Phone Series Exposes Users to Command Injection Attack

01 March 2023
Cisco on Wednesday rolled out security updates to address a critical flaw impacting its IP Phone 6800, 7800, 7900, and 8800 Series products. The vulnerability, tracked as CVE-2023-20078, is rated 9.8 out of 10 on the CVSS scoring system and is described as a command injection bug in the web-based management interface arising due to insufficient validation of user-supplied input. Successful

Research found 53% gap between best and worst email security solutions

01 March 2023
A recent report analyzed medium and small businesses' email security solutions' popularity and incidence defense between 2018 and 2022.   

Thirty-one percent of former employees still have company SaaS access

01 March 2023
SaaS report quantifies the volume, types and exposure risk of business assets stored within the SaaS estates of medium and large companies. 

Leveraging the Traffic Light Protocol helps CISOs share threat data effectively

01 March 2023
EXECUTIVE SUMMARY: As cyber threats continue to evolve and become increasingly sophisticated, it is critical for organizations to share threat intelligence to stay ahead of potential attacks. However, sharing sensitive information can be a challenge, as doing so requires a balance between the actual sharing of information and the need to protect it. This is […] The post Leveraging the Traffic Light Protocol helps CISOs share threat data effectively appeared first on CyberTalk.

BlackLotus Becomes First UEFI Bootkit Malware to Bypass Secure Boot on Windows 11

01 March 2023
A stealthy Unified Extensible Firmware Interface (UEFI) bootkit called BlackLotus has become the first publicly known malware capable of bypassing Secure Boot defenses, making it a potent threat in the cyber landscape.

Covert cyberattacks on the rise as attackers shift tactics for maximum impact

01 March 2023
2022 was the second-highest year on record for global ransomware attempts, as well as an 87% increase in IoT malware and a record number of cryptojacking attacks (139.3 million), according to SonicWall.

Critical Vulnerabilities Patched in ThingWorx, Kepware IIoT Products

01 March 2023
Several industrial IoT (IIoT) software products made by PTC are affected by two critical vulnerabilities that can be exploited for denial-of-service (DoS) attacks and remote code execution.

Immuta Receives Strategic Investment from ServiceNow

01 March 2023
Immuta, a Boston, MA-based data security company, received an additional strategic investment from ServiceNow. The investment, which was in addition to the Series E funding round, will allow the company to continue growing its cloud offering.

Cybercriminals Targeting Law Firms with GootLoader and FakeUpdates Malware

01 March 2023
Six different law firms were targeted in January and February 2023 as part of two disparate threat campaigns distributing GootLoader and FakeUpdates (aka SocGholish) malware strains. GootLoader, active since late 2020, is a first-stage downloader that's capable of delivering a wide range of secondary payloads such as Cobalt Strike and ransomware. It notably employs search engine optimization (

Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting

01 March 2023
In 2022, Trend Micro researchers noticed that they updated SysUpdate, one of their custom malware families, to include new features and add malware infection support for the Linux platform.

Can You See It Now? An Emerging LockBit Campaign

01 March 2023
Researchers from FortiGuard Labs observed a new LockBit ransomware campaign during December 2022 and January 2023 using a combination of techniques effective against AV and EDR solutions.

Video Marketing Software Animker Leaking Trove of User Data

01 March 2023
A misconfigured database has exposed test and personal data belonging to over 700,000 users of the websites getshow.io (an all-in-one video marketing platform) and animaker.com (a DIY video animation software).

BlackLotus Becomes First UEFI Bootkit Malware to Bypass Secure Boot on Windows 11

01 March 2023
A stealthy Unified Extensible Firmware Interface (UEFI) bootkit called BlackLotus has become the first publicly known malware capable of bypassing Secure Boot, making it a potent threat in the cyber landscape. "This bootkit can run even on fully up-to-date Windows 11 systems with UEFI Secure Boot enabled," Slovak cybersecurity company ESET said in a report shared with The Hacker News. UEFI

Parallax RAT Targeting Cryptocurrency Firms with Sophisticated Injection Techniques

01 March 2023
Parallax RAT, besides gathering system metadata, is also capable of accessing data stored in the clipboard and even remotely rebooting or shutting down the compromised machine.

CISOs Are Stressed Out and It's Putting Companies at Risk

01 March 2023
Employee well-being has become a primary focus for many businesses. Even before the pandemic, the C-suite was acutely aware of how employee mental health impacts business outcomes.  But for cybersecurity professionals, stress has always been a part of the job. A new survey revealed that one of the most concerning aspects of employee mental health is how it impacts cybersecurity programs and,

Universal Decryptor for MortalKombat Ransomware Released

01 March 2023
A new decryptor for the MortalKombat ransomware is now available for download. Bitdefender has been monitoring the MortalKombat ransomware family since it first appeared online in January this year.

Gmail and Google Calendar Now Support Client-Side Encryption (CSE) to Boost Data Privacy

01 March 2023
Google has announced the general availability of client-side encryption (CSE) for Gmail and Calendar, months after piloting the feature in late 2022. The data privacy controls enable "even more organizations to become arbiters of their own data and the sole party deciding who has access to it," Google's Ganesh Chilakapati and Andy Wen said. To that end, users can send and receive emails or